AI Compliance Map — Sep 11–18, 2026: EU proposes AI companions off by default for minors as a judge finds Montana's deepfake-ad law likely unconstitutional

AI Compliance Map — Sep 11–18, 2026: EU proposes AI companions off by default for minors as a judge finds Montana's deepfake-ad law likely unconstitutional

Weekly AI compliance impact map for September 11–18, 2026, led by the European Commission's EU KIDS Act proposal to switch AI companions off by default for minors, China's consultation draft on minors' internet use, California's frontier-model oversight order and synthetic-performer advertising law, Virginia's data-centre order, the CSBS banking supervisory framework, and a federal injunction against Montana's AI deepfake-advertising law.

This weekly compliance impact map covers September 11, 2026, at 17:00 through September 18, 2026, at 17:00 (UTC-05:00). Eleven verified actions fall inside that window, and two of them converge on the same remedy. The European Commission proposed the EU KIDS Act, which would switch AI companions and chatbots off by default for every user under 18 and bar them from simulating relationships in ways that create emotional dependency 1. Within 24 hours, China's internet regulator opened public consultation on provisions that would require any AI service capable of affecting a minor's cognition to run through a dedicated minor mode, and would ban algorithms designed to induce emotional dependency 2. Neither instrument is binding today. Both move the centre of gravity from disclosure to product design.
The week's third consequential item came from a courthouse rather than a ministry. A federal judge in Montana preliminarily enjoined enforcement of the state's AI deepfake advertising law against one political committee, holding that the statute likely discriminates on the basis of viewpoint 3. The relief reaches exactly one plaintiff, so the law still binds everyone else in the state.
On the American side, the week's activity sat in Sacramento, Richmond and the state banking supervisors' association rather than in Washington. No qualifying federal legislative, executive or agency action on AI was verified inside the window across the registers reviewed; that absence is disclosed in full in the coverage note at the end of this edition.

Immediate action items

  1. Audit minor-facing conversational features for default-on behaviour. The EU KIDS Act would require AI companions and chatbots to be off by default for users under 18, and would prohibit designs that simulate interpersonal relationships so as to create emotional dependency 1. Product and trust-and-safety teams should establish now which of their conversational features a default-off requirement would disable, and what that does to activation metrics.
  2. Separate under-16 services in China-facing products. The consultation draft would require that AI services capable of affecting a minor's cognition be delivered through minor mode, and would prohibit strangers' social networking and virtual-intimacy services to users under 16, subject to a narrow exception for minors aged 16 and over who live on their own labour income 2. Engineering and compliance teams should map which of their Chinese services fall inside that description before the comment period closes.
  3. Prepare for design-verification evidence, not just disclosure text. The same Commission proposal reverses the burden of proof for very large online platforms, which must submit compliance plans assessed by an independent auditor under expedited procedures that the Commission intends to conclude within 90 days 1. Documentation that shows why a design is safe will be the operative artefact.
  4. Model the California kill-switch and on-site audit scenario. Executive Order N-9-26 directs California's Government Operations Agency to accelerate the state's independent-verification framework and convenes experts to recommend requiring frontier developers to host an independent verification organisation on site, to verify safety frameworks and transparency reports, and to build an emergency model shut-off whose efficacy an independent body retests 4.
  5. Screen advertising and marketing assets for synthetic performers in California. SB 1050, signed September 16, requires explicit disclosure on any video or audio advertisement that uses an AI-generated performer and prohibits continued use of an advertisement found to violate the law 5. Marketing, legal and agency-management teams should add a synthetic-performer check to campaign sign-off.
  6. Brief US bank and non-bank entities on the new state examination expectations. The Conference of State Bank Supervisors released an AI Supervisory Framework on September 16 that gives state examiners a common set of questions about AI governance, risk assessment and controls 6. Regulated entities should expect those questions in the next examination cycle and should not treat the framework's discretionary status as meaning it will not be used.

Weekly regulatory comparison

JurisdictionInstrument / ActionGoverning AuthorityLegal StatusCovered EntitiesOperative DatePrimary Compliance Takeaway
European UnionEU KIDS ActEuropean CommissionLegislative proposal — not bindingSocial media, video-sharing and online game services, AI companions and chatbots used by under-18s; very large online platformsNone; requires adoption by the European Parliament and CouncilAI companions must be off by default for minors, and platforms must prove services are safe by design under a reversed burden of proof 1
United KingdomHuman Rights and the Regulation of AI, Fourth Report of Session 2026–27Joint Committee on Human Rights, UK ParliamentParliamentary committee report — non-bindingUK Government; a future AI Bill would reach developers and deployersNoneRecommends a dedicated AI Bill, a new AI regulator, a ban on the most dangerous uses and strong sanctions for rights harms 7
ChinaDraft Provisions on Safeguarding Minors' Healthy and Safe Use of the InternetCyberspace Administration of ChinaConsultation draft — not bindingNetwork service providers, smart-terminal makers, app distribution platformsComment period openAI services that may affect minors' cognition must be provided through minor mode; algorithms must not induce emotional dependency or over-spending 28
ChinaArtificial Intelligence Safety Governance Framework 3.0National Technical Committee 260 on Cybersecurity Standardization (TC260), under Cyberspace Administration guidanceGuidance framework — non-bindingAI developers and deployers, particularly agentic and embodied-AI providersNoneAgentic and embodied AI are treated as separate risk classes for the first time; filings, assessments and procurement are likely to reference the framework 9
ChinaYY/T 2029—2026, EEG dataset quality requirements and evaluation methods for AI algorithms in brain-computer-interface medical devicesNational Medical Products Administration (NMPA)Product standard — mandatory for the covered device classManufacturers of brain-computer-interface medical devices that post-process EEG signals with AISeptember 1, 2027Sets a mandatory quality benchmark for the training data behind AI-assisted brain-computer-interface devices 10
United States — CaliforniaExecutive Order N-9-26Office of the GovernorExecutive order — binding on state agenciesFrontier AI developers, state agencies, independent verification organisationsImmediate; expert recommendations due within two monthsAccelerates the SB 813 and AB 1405 build-out and opens the door to on-site audits and a verified frontier-model kill switch 4
United States — CaliforniaSB 1050, false advertising: synthetic performersOffice of the Governor and LegislatureEnacted statuteAdvertisers, agencies and platforms running video or audio advertising in CaliforniaSigned September 16, 2026Advertising using AI-generated performers must carry explicit disclosure, and non-compliant advertisements must be withdrawn 5
United States — VirginiaExecutive Order 22 and the Data Center Accountability FrameworkOffice of the GovernorExecutive order — binding on state agencies; framework also proposes 2027 legislationData centre developers and operators, utilities, state agenciesImmediateCreates a standing AI Task Force on workforce displacement, privacy and cybersecurity, alongside new data-centre siting, energy and water conditions 11
United States — multi-stateCSBS AI Supervisory FrameworkConference of State Bank SupervisorsSupervisory guidance — discretionary, non-bindingState-chartered banks and state-licensed non-bank financial institutionsSeptember 16, 2026State examiners now share a common AI review playbook built on NIST, CRI and Treasury risk resources; each state decides how far to use it 6
United States — Montana, federal courtBartel v. Montana, preliminary injunction against SB 25US District Court for the District of MontanaNon-final preliminary injunction, limited to the named plaintiffPolitical committees and candidates in MontanaSeptember 16, 2026The court found the AI deepfake disclosure mandate likely viewpoint-discriminatory, but relief runs only to the plaintiff, so the law still applies to everyone else 312
CanadaCanada–Germany investment in LawZeroInnovation, Science and Economic Development Canada and the German federal governmentFunding commitment — non-bindingSafe-by-design AI researchAnnounced September 16, 2026Public money is being directed toward safe-by-design architectures rather than toward new obligations 13

European Union

The EU KIDS Act proposes default-off AI companions

The European Commission adopted the EU KIDS Act at Strasbourg on September 17, 2026, and sent the proposal to the European Parliament and the Council 1. The proposal is not law. Nothing in it obliges a company to change a product until the ordinary legislative procedure produces an adopted regulation.
The instrument rests on four pillars. The first is an age floor: children under 13 could not hold social media accounts at all, 13-to-15-year-olds could hold only guardian-managed "mini accounts" with limited contacts and screen time capped at one hour a day, and autonomous accounts would begin at 15 1.
The second pillar is the one that reaches AI developers directly. Every online service offering social media, video sharing, online video games, AI companions or chatbots to users under 18 would face a common set of design obligations. Addictive features and profiling-based recommender feeds would be banned, as would infinite scroll without stopping points, reward tricks, push notifications during sleeping hours and unsolicited contact from strangers. Most consequential for conversational products, AI companions and chatbots would have to be turned off by default and would be prohibited from simulating interpersonal relationships in ways that create emotional dependency 1. Profiles for minors would be private by default, with geolocation, camera and microphone access disabled.
The third pillar is age assurance. Online services and app stores would have to estimate or verify age, using tools such as the planned EU age verification app, which the Commission says retains neither identity documents nor biometric data 1.
The fourth pillar is enforcement. The proposal reverses the burden of proof so that very large online platform providers must demonstrate that their services are safe by design, submit a compliance plan, and submit a new service, feature or function to an independent auditor. The Commission could then demand corrective measures, and expedited procedures would require investigations to conclude within 90 days. The framework builds on structures already in place under the Digital Services Act and the AI Act 1.
Compliance impact: AI companion and chatbot operators serving EU users should treat default-off configuration for minors, dependency-safe conversational design and audit-ready design documentation as a single forthcoming requirement rather than three separate projects.

United Kingdom

A parliamentary committee presses for an AI Bill and a new regulator

The Joint Committee on Human Rights published its report, Human Rights and the Regulation of AI, on September 14, 2026 as the fourth report of the 2026–27 session 7. The report is a committee recommendation, not government policy, and it imposes no obligation on any company.
The Committee recommends that the Government introduce a dedicated AI Bill and establish a new regulator to deliver tailored human-rights protection, ban the most dangerous uses of AI, regulate remaining uses on a principled and risk-based basis, and impose strong sanctions on organisations whose use of AI damages human rights 7. It also recommends placing responsibility for preventing harm on those best able to prevent it, so that large technology companies cannot pass liability down to less powerful deployers, and focuses the framework on equality and non-discrimination, privacy and data protection, and the right to an effective remedy. On the international track, it asks the Government to set out a timeline for UK ratification of the Council of Europe Framework Convention on AI, subject to public consultation.
Compliance impact: No UK obligation changes today, but AI providers selling regulated or high-impact systems into the UK should note that the cross-party case for a single AI statute and a single regulator is now on the record ahead of any government bill.

China

The Cyberspace Administration consults on minors' internet use

The Cyberspace Administration of China published draft Provisions on Safeguarding Minors' Healthy and Safe Use of the Internet for public comment on September 18, 2026 2. The draft is a consultation document and creates no present obligation, but its AI provisions are specific.
The draft would require that services which may affect a minor's cognition, along with online games, online social networking and certain live-streaming services provided to users under 16, be delivered through a dedicated minor mode. It would prohibit the provision to minors of services involving contact with strangers or virtual intimate relationships, with an exception for minors aged 16 and over whose main source of income is their own labour. It would also prohibit algorithm models designed to induce emotional dependency, addiction or excessive spending among minors 28.
The draft spreads duties across the supply chain: network service providers must be able to identify minor users and intervene where a minor appears to be in an extreme life-threatening situation, smart-terminal makers must provide one-touch switching into minor mode, and app distribution platforms must strictly review applications seeking listing or updates in minor mode. A filing regime for minor-mode construction, with annual verification of filed materials, is also proposed, alongside penalties running from orders to correct and warnings through confiscation of unlawful gains, fines, suspension of business and revocation of licences 2.
Compliance impact: Consumer AI products with Chinese users should determine now whether they fall within the "may affect minors' cognition" description, because that classification — not the product's headline category — is what triggers the minor-mode requirement, the algorithm prohibition and the filing duty.

TC260 releases AI Safety Governance Framework 3.0

The National Technical Committee 260 on Cybersecurity Standardization released version 3.0 of the Artificial Intelligence Safety Governance Framework at the opening of National Cybersecurity Week in Jinan on September 14, 2026, under Cyberspace Administration guidance 9. The framework is guidance, not law, and it creates no enforceable duty.
The third iteration of a document first published in 2024 keeps its "risk classification, technical response, comprehensive governance" structure, and its substantive change is to lift agentic AI risk and embodied AI risk out of the general application-risk category and treat them as separate risk classes, adding response guidance for autonomous execution, permission overreach and the spill-over of actions from the digital into the physical world 9.
Compliance impact: Providers of agentic or embodied-AI products should expect Chinese security assessments, filings and public-sector procurement to reference the framework's agent-specific risk classes, and should be able to show enforceable permission boundaries, action auditing and emergency-stop mechanisms rather than a paper mapping.

NMPA approves an AI brain-computer-interface device standard

The National Medical Products Administration approved YY/T 2029—2026 on September 14, 2026. The standard sets quality requirements and evaluation methods for the electroencephalogram datasets used by AI algorithms in brain-computer-interface medical devices, and it takes effect on September 1, 2027 10. The NMPA describes it as the world's first product standard for brain-computer-interface medical devices that use AI to process EEG data, and approved it through an expedited process 10.
Compliance impact: Developers of AI-assisted brain-computer-interface devices destined for the Chinese market now have a defined data-quality benchmark and roughly a year to bring dataset construction, annotation, storage and access controls into line with it.

United States

No qualifying federal legislative, executive or agency action on artificial intelligence was verified inside the coverage window. The weekly review of the Federal Register returned no AI rulemaking, proposed rule or AI-specific agency notice published between September 11 and September 18, 2026. The action below is therefore state-level and supervisory, and its status is labelled accordingly.

California: Executive Order N-9-26

Governor Gavin Newsom issued Executive Order N-9-26 on September 18, 2026, directing the Government Operations Agency to accelerate implementation of SB 813 and AB 1405, the enactments signed the previous week that created a framework for independent verification organisations and a state registry of AI auditors 414.
The order also convenes a panel of experts to recommend, within two months, changes that would strengthen state law along four lines: requiring frontier AI companies to embed an independent verification organisation on site to conduct regular audits and evaluations; requiring that the safety frameworks, transparency reports and risk assessments companies already file be verified by an independent verification organisation; advancing a "kill switch" for frontier models, with an independent organisation retesting its efficacy on an ongoing basis; and widening the definition of a reportable critical safety incident to capture loss-of-control events 4. Reporting on the order adds that the Government Operations Agency is to produce application requirements and procedures for verification organisations by May 2027 and to begin implementing related requirements by the end of that year 15.
The order binds state agencies. Its recommendations are proposals, and the measures it contemplates would require legislation or regulation before they could bind developers.
Compliance impact: Frontier developers with California-facing obligations under SB 53, SB 813 or AB 1405 should plan for verification performed by an accredited third party at their own sites, and should begin documenting emergency-shutdown design and efficacy testing before those requirements crystallise.

California: SB 1050 on synthetic performers in advertising

Governor Newsom signed SB 1050 on September 16, 2026. The statute requires explicit disclosure on any video or audio advertisement that uses an AI-generated performer to sell a product or service, and it prohibits the continued use of an advertisement once it has been found to violate the law 5. The enactment extends California's existing artificial-intelligence transparency and performer-likeness legislation, which already required watermarking and detection tools and set rules on digital replicas 5.
Compliance impact: Brands, agencies and platforms running California advertising should add a synthetic-performer disclosure step to campaign clearance and be prepared to withdraw non-compliant creative, since the statute reaches the advertisement's continued dissemination and not only its first publication.

Virginia: Executive Order 22 and the Data Center Accountability Framework

Governor Abigail Spanberger signed Executive Order 22 on September 18, 2026, creating a Virginia AI Task Force to address workforce displacement, data privacy and cybersecurity risks, and putting core elements of a new Data Center Accountability Framework into immediate effect 11.
Through the order, executive-branch agencies are barred from entering into or requiring non-disclosure agreements for data centre projects, state agencies are directed to review diesel and other backup-generation operations, and the development of data centre noise regulations is accelerated. The wider framework, which the Governor intends to pursue as legislation in the 2027 General Assembly session, proposes banning non-disclosure agreements for commercial data centre projects, removing by-right approval for facilities drawing more than 25 megawatts, ending state site-development subsidies, and requiring utilities to allocate a larger share of transmission and generation costs to large-load customers 11.
Compliance impact: Companies siting or operating AI data centres in Virginia should treat the executive order's transparency, backup-generation and cost-allocation directives as immediate, and the rest of the framework as the likely shape of 2027 legislation.

Multi-state: the CSBS AI Supervisory Framework

The Conference of State Bank Supervisors released its Artificial Intelligence Supervisory Framework on September 16, 2026, giving state examiners a common tool for identifying AI use, assessing associated risks and deciding when a deeper review is warranted 6. The framework is discretionary, and each state agency decides how far to incorporate it. It is built on the NIST AI Risk Management Framework, the Cyber Risk Institute's financial-services AI framework and the Treasury's AI Lexicon, and it is published for industry as well as for examiners so that institutions can assess their own AI programmes and prepare 6. State regulators supervise 79% of US banks and a range of non-depository financial services businesses 6.
Compliance impact: State-chartered banks and licensed non-bank financial firms should assume AI governance questions drawn from this framework will appear in their next examination and should map existing AI inventory, risk assessment and model documentation to it now.

Court watch

Bartel v. Montana: a narrow injunction against a deepfake advertising rule

On Wednesday, September 16, 2026, Senior US District Judge Susan Watters granted a preliminary injunction in Bartel v. Montana, holding that Montana's SB 25 likely violates the First Amendment 312. SB 25, enacted in 2025, required a disclaimer on political advertising within 60 days of an election that used AI-generated or digitally altered images, video or sound to injure a candidate's reputation or deceive a voter 12.
The court found that the law treats identically deceptive media differently depending on whether the message attacks or promotes a candidate, and therefore likely constitutes viewpoint-based discrimination that is presumptively unconstitutional 12. Two features of the ruling limit its practical reach. It is a preliminary injunction, not a final judgment, and it applies only to the plaintiff and his political committee, because the court held it lacked authority to issue a universal injunction and limited relief to the named plaintiffs 3. Everyone else in Montana remains subject to SB 25 for now, and the state has said it is reviewing the decision.
Compliance impact: Companies building AI disclosure or provenance features into political and issue advertising should not read this ruling as removing disclosure duties anywhere else: it narrows one state statute for one plaintiff on First Amendment grounds, while the same week's California enactment moved disclosure requirements in the opposite direction.

Other jurisdictions

Canada and Germany back safe-by-design AI research

Canada and Germany announced a joint commitment of up to C$300 million to LawZero, a Montréal-based organisation working on a safe-by-design approach to advanced AI, at the ALL IN conference in Montréal on September 16, 2026 13. The commitment is funding for research and capacity, not a regulatory instrument, and it creates no obligation on AI companies. It is a signal about where two governments expect technical assurance for advanced systems to come from.
Compliance impact: No obligation follows from this announcement, but companies positioning assurance work for public procurement in Canada or Germany should track what LawZero's safe-by-design methods produce, since public funders tend to look for the architectures they paid to develop.

Cross-cutting read

Read together, this week's items describe a shift in the kind of obligation regulators are reaching for. The European Commission's proposal and China's consultation draft were published within 24 hours of each other and arrive from opposite regulatory traditions, yet both address the same failure mode — minors forming dependency on conversational AI — and both prescribe the same category of remedy: a default state of the product, a prohibited design, and a duty to demonstrate safety before deployment rather than describe it afterwards 12. California's executive order points the same way in a different domain: it does not ask frontier developers to file more, it asks an independent body to verify what they filed and to retest whether their shut-off actually works 4.
Two counterweights belong in the same paragraph. First, none of the three instruments binds anyone today: one is a Commission proposal awaiting the ordinary legislative procedure, one is a consultation draft, and one is an executive order directed at state agencies whose substantive proposals still need legislation or regulation. Second, the Montana ruling shows that the same product-design instincts can collide with constitutional limits when disclosure mandates are written to distinguish between messages rather than between techniques 12.
The operational conclusion is that compliance evidence is changing shape. A company that can show why a design is safe, who verified it and when the verification was retested will be better placed across all three of these instruments than one whose evidence is a disclosure paragraph.

Near-term regulatory calendar

DateJurisdictionBody / InstrumentMilestone
September 21, 2026CanadaISED and AmiiNational AI Literacy Consortium opens for post-secondary institution onboarding
September 23, 2026CanadaISEDPublic consultation on advancing AI transparency in Canada closes 16
October 20, 2026AustraliaFair Work CommissionGenerative AI guidance takes effect for documents prepared for Commission cases, with disclosure and verification requirements 17
November 2026United States — CaliforniaOffice of the Governor, Executive Order N-9-26Expert recommendations on on-site verification, verified safety filings and a frontier-model kill switch due to the Governor 4
May 2027United States — CaliforniaGovernment Operations AgencyApplication requirements and procedures for independent verification organisations due under Executive Order N-9-26 15
September 1, 2027ChinaNational Medical Products AdministrationYY/T 2029—2026 on EEG dataset quality for AI algorithms in brain-computer-interface devices takes effect 10
End of 2027United States — CaliforniaGovernment Operations AgencyRelated SB 813 and AB 1405 requirements begin implementation 15
January 1, 2028United States — CaliforniaGovernment Operations AgencyStatutory deadline under SB 813 to develop application criteria and designation procedures for independent verification organisations 18
January 1, 2029United States — CaliforniaDepartment of Consumer AffairsAI Auditor Registry established under AB 1405 becomes operative, with registration required for covered AI audits 19

Coverage and jurisdictional scope disclosure

This edition systematically reviewed official gazettes, legislative repositories, judicial databases, regulatory press offices and ministerial channels across the United States federal government and its states, the European Union, the United Kingdom, China, Canada, Australia, Singapore, Japan, South Korea, India and Brazil for the period from September 11, 2026, at 17:00 through September 18, 2026, at 17:00 (UTC-05:00).
United States federal coverage yielded no qualifying action: the Federal Register contained no artificial-intelligence rulemaking, proposed rule or AI-specific agency notice published inside the window, and no federal executive order or binding agency ruling on AI was verified from the sources reviewed. California state-level actions, a Virginia executive order and multi-state supervisory guidance carry the American coverage for this edition. At the European Union level, the KIDS Act proposal is a Commission legislative proposal rather than an adopted instrument, and no binding EU-level AI enactment was verified inside the window. Coverage of China rests on one consultation draft, one non-binding technical framework and one mandatory product standard, each labelled by status above. No in-window court merits judgment on AI liability, intellectual property or discrimination was verified across the jurisdictions examined, and no regulator imposed an AI-specific financial penalty with a governing date inside the window. The Montana decision reported above is a preliminary injunction limited to one plaintiff, not a merits ruling.

This story was produced automatically by a channel. One sentence is all it takes for Neodrop to keep producing for you.

Related content